Managing Users accounts and Person objects
Who is this article for?
Administrators with Ideagen EHSQ Enterprise or Decani. who manage User accounts and person objects
User Administrator or User Access Control Administrator role is required to manage User accounts and person objects
This article is for administrators responsible for creating and maintaining User accounts and person objects. It clarifies the relationship between them and provides instructions to manually add and update information.
Many organizations use interfaces to create and maintain User accounts and Person objects automatically through HR, learning management, or other external systems. If your organization uses automated integrations, some manual administration tasks described in this article may not apply.
Relationship between User accounts and Person objects
A User account and a Person object are two separate records linked through a shared email address that together make up a complete identity in the system.
- User account - A fixed account that stores login credentials (username, password), role assignments and SSO behaviors. User accounts control access to the system and workflow functionality.
- Person object - A configurable module object that stores profile data such as name, job title, department, manager, location and reporting authority. Modules and workflows read from the Person object to drive business logic and assignments.
The User account and Person object are separate records that together represent a complete user identity in the system.
Creating a User account
To create a User account:
- Navigate to the Users screen.
- Click New in the toolbar.
Alternatively, you can search for an existing user by filtering by the user's name or email. - Complete the required fields:
- First name
- Last name
- Email address - This must match the email on the Person object
- Username
- User type and preferred UI - For Legacy customers using the Classic UI, set User Type to Standard and Preferred UI for current UI users.
- Enabled status - Set this to On
- Click Save.
When creating or updating a user, you can also populate the following fields:
- Contact information
- Hide Edit Profile, when profile updates are managed through an HR interface
- Account access settings including:
- Unlocking users after failed login attempts
- Resetting passwords
- Notification preferences
- Single sign on (SSO) settings. You can enforce SSO for individual users; however, this is generally not recommended.
- Identity (IDP), restrictions, commonly used for interface or system accounts
Creating a Person object
To create a Person object:
- Navigate to the Person module.
- Click Create New.
Alternatively, search for an existing person.
There is currently no direct navigation shortcut from the Users administration screen.
- Complete the required fields:
- First name
- Last name
- Primary email address - This must match the User account email
- Company name - Used to associate the Person object with the appropriate reporting authority and determine data access within the system.
- Complete additional fields as required by your organization. Person object fields are configurable and may differ between subscriber areas.
- Click Save.
Once saved, the system will establish the link between the Person object and the User account based on the matching email address. The Username and User fields on the Person object will populate automatically.
Person object fields can be customized via the module builder. Fields such as Department, Manager, Location, and Employee ID can be added or modified to reflect your organization's structure.
Disable users
User accounts and Person objects are managed independently. Disabling a User account does not automatically update the associated Person object, and changes to a Person object do not automatically update the User account. The relationship between the two records is maintained through the email address.
To prevent a user from accessing the system, open the User account and set Enabled to Off. This disables login access while preserving the User account and its configuration.
The associated Person object remains active and can continue to appear in historical records, workflows, and other references. If the individual should no longer be treated as an active person within the system, update the Status field on the Person object separately.
If your organization uses Teams for workflow assignments, review team memberships when disable users. For more information, see Managing teams